Juniper
JN0-633 · Question #187
Click the Exhibit button.Traffic is being sent from Host-1 to Host-2 through an IPsec VPN. In this process, SRX-2 is using NAT to change the destination address of Host-2 from 192.168.1.1 to…
The correct answer is C. The security policy on SRX-2 must permit traffic from the 10.60.60.1 destination address. See the full explanation below for the reasoning.
Question
Click the Exhibit button.Traffic is being sent from Host-1 to Host-2 through an IPsec VPN. In this process, SRX-2 is using NAT to change the destination address of Host-2 from 192.168.1.1 to 10.60.60.1 SRX-1 uses the 172.31.50.1 address for its tunnel endpoint and SRX-2 uses the 10.10.50.1 address for its tunnel endpoint. Referring to the exhibit, which statement is true?
Exhibit
Options
- AThe security policy on SRX-2 must permit traffic from the 172.31.50.1 destination address.
- BThe security policy on SRX-2 must permit traffic from the 10.10.50.1destination address.
- CThe security policy on SRX-2 must permit traffic from the 10.60.60.1 destination address.
- DThe security policy on SRX-2 must permit traffic from the 192.168.1.1destination address.
How the community answered
(31 responses)- A13% (4)
- B6% (2)
- C77% (24)
- D3% (1)
Community Discussion
No community discussion yet for this question.
